
Maintenance Page Security & Risk Analysis
wordpress.org/plugins/maintenance-pageAllows you to quickly create a maintenance/coming-soon page. Use this plugin whenever your site is down for maintenance or undergoing development.
Is Maintenance Page Safe to Use in 2026?
Mostly Safe
Score 84/100Maintenance Page is generally safe to use though it hasn't been updated recently. 2 past CVEs were resolved. Keep it updated.
The "maintenance-page" plugin v1.0.9 exhibits a mixed security posture. While it demonstrates several good security practices, such as having a relatively small attack surface with only one AJAX handler and implementing nonce and capability checks for some entry points, there are significant concerns. The presence of the `create_function` function is a red flag, as it is deprecated and can be a source of vulnerabilities if not handled with extreme care. Furthermore, 100% of SQL queries are not using prepared statements, which poses a risk of SQL injection vulnerabilities, especially when dealing with user-supplied input. The fact that only 50% of output is properly escaped also indicates potential cross-site scripting (XSS) vulnerabilities. While there are no currently unpatched CVEs, the plugin has a history of two medium-severity vulnerabilities, both related to improper access control. This history, coupled with the code signals like unescaped output and raw SQL queries, suggests a pattern of potential security weaknesses that require careful attention. The absence of taint analysis results, while not necessarily indicative of a problem on its own, means that potential data flow vulnerabilities might not have been detected. In conclusion, while the plugin has some positive security attributes, the identified code signals and historical vulnerability patterns point to areas that need immediate attention to improve its overall security.
Key Concerns
- Dangerous function detected (create_function)
- Raw SQL queries without prepared statements
- Only 50% of output is properly escaped
- Two medium severity vulnerabilities in history
Maintenance Page Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Maintenance Page <= 1.0.8 - Missing Authorization to Sensitive Information Exposure
Maintenance Page <= 1.0.8 - Security Mechanism Bypass via REST API
Maintenance Page Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Maintenance Page Attack Surface
AJAX Handlers 1
WordPress Hooks 10
Maintenance & Trust
Maintenance Page Maintenance & Trust
Maintenance Signals
Community Trust
Maintenance Page Alternatives
Super Easy Maintenance Mode – Coming Soon & Under Construction
super-easy-maintenance-mode
Enable coming soon page, maintenance mode, under construction page in just one click toggle.
Build Mode – Maintenance Mode & Coming Soon Page
build-mode
Maintenance Mode & Coming Soon Made Easy – Display any page as your maintenance or coming-soon screen, no coding required.
Maintenance
maintenance
Great looking maintenance, coming soon & under construction pages. Put your site under maintenance in minutes.
CMP – Coming Soon & Maintenance Plugin by NiteoThemes
cmp-coming-soon-maintenance
Beautiful Coming soon, Maintenance or Landing page on your website, packed with premium features for free.
Coming Soon & Maintenance Mode Page & Under Construction
nifty-coming-soon-and-under-construction-page
Nifty Coming Soon & Maintenance Page creates awesome Coming Soon & Maintenance Pages.
Maintenance Page Developer Profile
31 plugins · 252K total installs
How We Detect Maintenance Page
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/maintenance-page/public/css/maintenance-page.css/wp-content/plugins/maintenance-page/public/js/maintenance-page.jsmaintenance-page/public/css/maintenance-page.css?ver=maintenance-page/public/js/maintenance-page.js?ver=HTML / DOM Fingerprints
mp-subscribe-formMaintenancePage/wp-json/maintenance-page/v1/subscribe